Network Security

What's actually reachable from the internet in my cloud?

Security groups are one layer. Your attack surface has seven.

Most tools tell you which security groups have port 22 open. Onam traces the full 7-layer network path — from VPC isolation to WAF coverage and flow log monitoring — and shows what's actually reachable from the internet, not just what the rules say.

10,000+
security rules
7
cloud providers
< 5 min
to first finding
100%
agentless
Why this matters

Your security group review says port 22 is closed.

But the instance sits in a public subnet, behind a load balancer that terminates TLS, in a VPC peered to a shared network where a jump host has SSH open to the world. On paper you are safe. In practice a single hop reaches the database. Rules alone lie; only reachability tells the truth.

The risk of not knowing

If it is not surfaced today, it is exposed today. Attackers do not wait for your quarterly review — and neither do auditors.

Real-time detection, not periodic audits
How does it actually work?

The mechanism, not the marketing

  1. 1

    Onam pulls every network object across your clouds — VPCs, subnets, route tables, NACLs, security groups, load balancers, WAFs, transit gateways, peerings.

  2. 2

    The engine models them as a graph and runs reachability analysis: given an internet source, what resources can actually receive traffic, on which ports, over how many hops.

  3. 3

    Each resource gets an effective exposure score that reflects the true path, not just the closest security group.

  4. 4

    Coverage gaps — subnets without flow logs, load balancers without WAFs, missing TLS enforcement — are surfaced separately.

  5. 5

    Findings refresh continuously as networks change, so a new peering or a shifted route table shows up within minutes.

What do you actually get?

Specific outputs, measurable outcomes

Effective exposure score for every resource
Security group audit
overly permissive inbound on SSH, RDP, DB ports
Subnet classification
truly private vs publicly accessible
NACL analysis
Load balancer security
TLS version, HTTP→HTTPS redirect, internet-facing exposure
WAF coverage map
Flow log coverage gaps
VPC peering and transit gateway exposure analysis
See it live

Network Security in the real console.

Not a mockup — the actual Onam console on a live demo account, showing exactly what your team sees.

Network Security
Export Topology
5
VPCs
47
Security Groups
7
Internet-Exposed
23
Open Ports
Loading live data…
Your network edge, mapped
5 VPCs, 47 security groups — 7 internet-exposed resources with exact fix actions
Clip length
10s
Data
Demo account
FAQ

Questions we get a lot

No. AWS VPCs, Azure VNets, GCP VPCs, OCI VCNs, Alibaba VPCs, and Kubernetes network policies are all analysed on the same reachability graph. Peering, transit, and cross-cloud connectivity are modelled end to end.
Ready to see it live

Ready to see Network Security in your cloud?

Connect a read-only role in three minutes. Your first findings surface in under five.